Policy center

Last updated May 31, 2026

Privacy Policy

How Shuffle Resume collects, uses, stores, and deletes account, provider, queue, and billing data.

Data we collect

We collect account profile data from your sign-in provider, such as your name, email address, profile image, provider account identifier, OAuth scopes, and token expiry information.

We store provider OAuth tokens server-side so the app can authenticate Spotify, Apple Music, Google/YouTube, and TIDAL connections, create supported private provider playlists, resume saved sessions, and refresh access when a provider allows it.

We store queue/session data, including session title, description, provider, ordered track or video identifiers, shuffle order, current resume index, playlist identifier, status, and timestamps.

We store billing metadata from Stripe, including customer id, subscription id, price id, billing interval, subscription status, entitlement state, and signed webhook event ids for idempotency.

If you use play history sync, we store limited playback metadata such as provider, track URI, track name, artist, and played-at time so the app can support resume and history features.

How we use data

We use account and provider data to authenticate you, connect your music account, create supported private playlists, add selected tracks or videos in saved order, resume saved queues, and keep provider handoffs working.

We use billing data to create Stripe Checkout sessions, manage subscriptions, process Stripe webhooks, and determine whether paid features are available.

We use queue/session data to preserve deterministic shuffle order and current resume position across devices.

We use request metadata, rate-limit keys, and safe logs to protect the service, troubleshoot failures, and investigate abuse without logging secrets or full OAuth tokens.

Server-side and client-side storage

Server-side storage includes the database records for users, provider accounts, sessions, queue sessions, subscriptions, webhook events, preferences, play events, and deletion requests.

Client-side storage is limited to necessary app state such as NextAuth cookies, OAuth PKCE cookies, a no-repeat preference in localStorage, a checkout idempotency key in sessionStorage, and cached static app assets from the service worker.

Provider tokens, Stripe secrets, Apple private keys, database URLs, webhook secrets, and OAuth client secrets are not intentionally exposed to the browser bundle.

Deletion, correction, and disconnect

You can disconnect a provider account from Apps. Disconnecting removes that provider account record, server-side token material, provider-specific saved queues, provider play events, and Spotify shuffle history where applicable.

You can also revoke app access from the connected provider's account settings where the provider offers that control, including Google account permissions at https://security.google.com/settings/security/permissions.

You can request account deletion from Apps by confirming the deletion action. The app clears provider tokens, marks your account for deletion, creates a deletion request, and sets eligible Stripe subscriptions to cancel at period end.

Provider API data associated with a disconnected account or account deletion request is removed from active app records through the disconnect or deletion workflow. Where any remaining YouTube API data is identified, it will be deleted within 30 calendar days unless retention is required for security, fraud prevention, legal compliance, or dispute records.

Deletion requests currently enter a 30-day recovery window before operational removal. If you need correction, deletion, or access help, contact privacy@ocoferudition.com.

Access and portability

The current app does not yet provide a self-service data export button.

You can request access to, correction of, or a portable copy of account, provider-connection, billing-status, and saved-session data by contacting privacy@ocoferudition.com from the email tied to your account.

We may need to verify the request and may retain limited billing, security, abuse-prevention, or legal records when required.

Sharing

We share data with Spotify, Apple, Google/YouTube, TIDAL, and Stripe only as needed to authenticate, create supported provider playlists, resume sessions, or process billing.

We host and operate the app through infrastructure providers such as Hostinger, Neon/Postgres, and Upstash Redis where configured. Those providers may process request metadata and operational logs as needed to deliver, secure, and monitor the service.

We do not sell personal data and do not use provider content, provider API data, provider tokens, or play history for advertising profiles or model training.

Where Google API data is involved, Shuffle Resume's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Provider terms

Your use of Spotify, Apple Music, YouTube, and TIDAL through Shuffle Resume remains subject to the account, subscription, privacy, and usage terms of those providers.

Provider-specific details are described in the Provider Data Handling Policy, Apple Data Handling Policy, Spotify Compliance and Playback Use Policy, YouTube API Services Data Policy, and TIDAL Data Handling Policy.